Wallet interoperability and reliability: bounded sync, proof recovery and BRC-118 payments - #569
ty-everett wants to merge 29 commits into
Conversation
Preserve asynchronous transport errors, authorization timing and queue ownership with regression coverage. Reconcile the AuthSocket patch candidate for changed bundled SDK bytes and clarify the empty-body migration exception.
# Conflicts: # docs/packages/sdk/bsv-sdk.md # docs/reference/package-api-migrations.md # docs/reference/stack-facts.md # governance/package-release-notes.json # governance/repository-health/baselines.json # packages/sdk/CHANGELOG.md # packages/sdk/README.md # packages/sdk/package.json
# Conflicts: # docs/reference/package-api-migrations.md # governance/package-release-notes.json
|
|
[administrative coordination note] The intention is NOT to merge this PR until after the five wallet releases (BSV Browser, BSV Desktop, Metanet Explorer Mobile, Metanet Client Desktop, and Peacock Wallet) are fully rolled out and in production, validated with users. This is a subsequent, later, follow-on change, designed for after the dust settles around the SDK 2.8.x series. Until then for this PR we have one mandate on the branch: keep CI green, keep it synced with main, address all review items, hold it open, continue adversarial review, and keep it healthy until AFTER all the wallet / 2.8.x work is done. Ensure its completeness. Likely merge timeline: perhaps Friday the 25th, with explicit human maintainer approval only. Agents: keep the branch green and free of conflicts meanwhile, so it will not be stale, and also address all review findings, while inviting further review. |



Wallet synchronization currently holds manager ownership across a whole transfer, so slow source I/O blocks foreground wallet work. Large HTTP payments also exceed practical header limits, and stale proof records can repeatedly poison otherwise spendable funding. This PR delivers a bounded resumable local sync path, canonical proof recovery and a complete prepared BRC-118 client/server payment path, with compatible PeerPay base64 reception.
Program and scope
proven_txsmakes everycreateActionthat selects that coin fail permanently withWERR_INTERNAL: merged Beef failed validation.#545, fix: PeerPayClient rejects BRC-29's documented base64 transaction, and no size check precedes broadcast #548, [QA] Complete deferred coverage, fuzzing, conformance, and runtime validation #400 and [Maintenance] Validate Sonar administration and continue CI efficiency review #402.syncFromReaderResumableyields ownership around source/proof I/O, commits one page and checkpoint atomically, reports progress, supports safe cancellation/resume and fences destination changes. Its new default is 256 KiB rough pages; existing sync APIs/defaults remain. Remote/custom providers retain safe exclusive fallback.c8820a4f7via merge commitf02333a3b(after the earlier110aae46fintegration ina4d625ade); the branch retains the published SDK 2.8.1/2.8.2, packaging fix: CommonJS builds bind @bsv/sdk default imports to whole modules (#571) #577 and Toolbox fix(wallet-toolbox): basket authorization, sendMax permissions, Monitor without push events, mobile exports #579 repairs. The SDK fix(sdk): preserve BRC100 discovery and signed action history #587 discovery/browser-fetch and signed-history fixes and MessageBox fix(messagebox): migrate durable HTTP authentication replay claims #588 replay-table migration plus fix(messagebox): consume SDK 2.8.3 and document proxy contracts #589 published SDK dependency/proxy guidance are retained exactly; review-update headf02333a3bis fully validated, with terminal successful hosted evidence below.Impact
Unpublished candidates: SDK 2.9.0; Toolbox core/client/mobile 2.15.0; auth middleware 2.3.0; payment middleware 2.2.0; MessageBox client 2.6.0; documentation-only 402-pay 0.3.3; templates 1.10.4. Packed dependency-range changes require patches for amountinator 2.1.7, did-client 1.3.4, fund-wallet 1.5.3, overlay-discovery-services 2.2.6, overlay-express 2.7.3, overlay-topics 1.8.5, simple 0.6.1 and wallet-helper 0.1.9. AuthSocket client 2.1.8 refreshes changed UMD bundle bytes after the SDK integration; its source API and event serialization remain unchanged. The release ledger preserves published baselines, including verified SDK 2.8.3 from protected release 35950850386.
Review update
-1sentinel afterexpress.raw, matching AuthFetch. Nineteen new cases cover byte helpers, actual POST/PUT authentication and signed responses, absent/nonempty bodies, in-transit tampering, and copied payload framing independent of shadowed byte-view length metadata. Both reproduced failures before the fixes.0require paired SDK 2.9.0/auth middleware 2.3.0 adoption. Nonempty preimages remain unchanged; README, guide and migration ledger document the boundary explicitly.Verification
Integrated-graph validation uses official Node 24.18.0 / pnpm 10.33.2; earlier completed workspace evidence used Node 24.19.0 where recorded:
pnpm build,pnpm typecheck,pnpm lint,pnpm format:check,pnpm health:check: pass; health has zero contract findings/control errors.pnpm audit:security: no known vulnerabilities. Frozen install passes.2b959b13f1f73040d13cc4eb14edbfc376f8010b.sdk-auth-http93.08%,auth-express-bytes90.16%,payment-replay96.30%; zero uncovered/invalid mutants. The mutation run exposed cancellation-test gaps that were repaired without changing the gate.pnpm docs:examples: 8 examples / 21 exact tarballs pass. Docs-site build/link checks pass. Current API pages, migration/release notes and explicit next-stage design are included.Fresh review-update performance fixture on
f02333a3b: 10,000 same-timestamp labels with tombstones, 64 x 32 KiB proofs and related transactions, 15 ms source latency, 256 KiB page target. Sequential measurements compare this branch's exclusive fallback with paged mode:Queue responsiveness does not eliminate synchronous HTTP crypto/encoding cost. Inclusive timestamp replay deliberately remains 45/47 pages for the all-tied fixture; settled unchanged copies use two. The guide records CPU, memory, wire/query counts, queue/commit measurements and reproducibility limits. These are fixture results, not device-wide latency guarantees.
Security and dependencies
CHROME_BINoverride.Dependency evidence
Release and operations
Completion evidence
Final head
f02333a3bb1fe1ceb764f1b4a18a4793758902cb: CI / merge gate, CodeQL, and Conformance are terminal successful. All 48 applicable check runs pass, including Codecov patch and strict Sonar; the one scope-based dependent-test skip is accepted by the merge gate. Zero open CodeQL alerts, zero new Sonar issues/hotspots, and all review conversations resolved with evidence. Latest mainc8820a4f7is incorporated, GitHub reports no conflicts, and auto-merge is disabled.Ready for maintainer re-review; sirdeggen's review has not been dismissed. No PR merge, publication or deployment is performed or authorized by this closeout.